Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

RevEye Reverse Image Search

keaaclcjhehbbapnphnmpiklalfhelgf
Risk Score
4.45
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Other
Installs 90,000
Rating 4.1
Last updated
Manifest version MV3
CSP present ❌ no
Developer steven2358@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy, not scoped to this extension; admits data collection and third-party sharing (→ Privacy +10.0).
  • Developer uses free Gmail address with no business domain; brand_mention flags Google impersonation.
  • No CSP declared (MV3 mitigates but no explicit policy); install_url_hijack opens internal whatsnew.html on install.
  • last_updated unknown — cannot rule out abandonment; maintenance scored conservatively at 6-month band.
  • Extension contacts 4 external search-engine hosts with no host_permissions declared; network surface matches function but increases reach.

Evidence

  • privacy_policy_generic store Policy URL is myaccount.google.com/privacypolicy — Google's global policy, scope_extension=false, data_collection=true, third_party_sharing=true → Privacy D rule → +10.0.
  • brand_impersonation store brand_mention.is_impersonation=true, brands_mentioned=[google], confirmed_owner=false, developer_domain=gmail.com.
  • free_webmail_developer manifest developer_email=steven2358@gmail.com; no developer_name; no business domain.
  • install_url_hijack crx install_url_hijack=true, target=whatsnew.html (internal). Lower severity than 3rd-party target but still flagged.
  • last_updated_missing store last_updated empty and months_since_update null; cannot confirm active maintenance — scored at 6-month stale band (+3.5).
  • js_external_hosts crx Contacts lens.google.com, www.bing.com, www.tineye.com, yandex.com — 4 domains, matches stated function (reverse image search).
  • verified_publisher store verified_publisher=true AND is_featured_by_google=true; discounts applied but capped per v3.5 invariant 0c (no resolving dev domain).
  • cve_findings_empty crx cve_findings_raw=[] and code_findings_raw=[]; no library CVEs or malicious code patterns detected.

Permissions Breakdown

  • contextMenus low Adds right-click menu items; low standalone risk.
  • storage low Local preference storage only; no exfil capability alone.

Pillar Scores

Permissions0.60
Reputation6.50
Network2.00
Webstore4.50
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Scoring History

&#x27;fsssiedxtfdsaxax><!--></ScRiPt>asddsssiedx 3.55 Low review 2026-08-22
&#x22;fsssiedxtfdsaxax><!--></ScRiPt>asddsssiedx 4.14 Medium review 2026-08-22
fsssiedxt<sssiedx 3.57 Low review 2026-08-22
<fsssiedxa&#x27;sssiedx 2.70 Low review 2026-08-22
<fsssiedxi"sssiedx 2.62 Low review 2026-08-22
fsssiedx<sssiedx 3.24 Low review 2026-08-22
%76%33%2E%36%39%30%33%38%22%28%29%3B%7D%5D%39%34%30%36 3.07 Low review 2026-08-05
v3.6/u0022onmouseover=OTcy(97083)/u0022 3.06 Low review 2026-08-05
1}}"}}'}}1%>"%>'%><%={{={@{#{${dfb}}%> 3.09 Low review 2026-08-05
bfg1118<s1﹥s2ʺs3ʹhjl1118 2.82 Low review 2026-08-05
v3.6&n930728=v981862 3.14 Low review 2026-08-05
<fsssiedxa"sssiedx 3.06 Low review 2026-08-01
<fsssiedxa'sssiedx 3.15 Low review 2026-08-01
<fsssiedxa&#x22;sssiedx 3.62 Low review 2026-08-01
<fsssiedxa$"sssiedx 3.56 Low review 2026-08-01
<fsssiedxa sssiedx 3.11 Low review 2026-08-01
<fsssiedxa 3.45 Low review 2026-08-01
<fsssiedxa$'sssiedx 3.33 Low review 2026-08-01
fsssiedxa<sssiedx 2.16 Low review 2026-08-01
&#x22;fsssiedxa<sssiedx 1.80 Low review 2026-08-01
&#x22;fsssiedxa"sssiedx 3.58 Low review 2026-08-01
&#x22;fsssiedxa&#x27;sssiedx 3.18 Low review 2026-08-01
3.41 Low review 2026-08-01
$"fsssiedxa 3.27 Low review 2026-08-01
$"fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 3.27 Low review 2026-08-01
$"fsssiedxa$'sssiedx 3.24 Low review 2026-08-01
fsssiedxa$"sssiedx 3.21 Low review 2026-08-01
fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 3.19 Low review 2026-07-31
sssieddrubricxsx 3.55 Low review 2026-07-31
v3.6</script><script>TiJ7(9524)</script> 3.62 Low review 2026-07-29
%76%33%2E%36%39%32%39%34%22%28%29%3B%7D%5D%39%34%38%34 3.09 Low review 2026-07-29
v3.6"onmouseover=TiJ7(94102)" 3.02 Low review 2026-07-29
"dfbzzzzzzzzbbbccccdddeeexca".replace("z","o") 3.09 Low review 2026-07-29
bfgx8957%C0%BEz1%C0%BCz2a%90bcxhjl8957 3.26 Low review 2026-07-29
dfb__${98991*97996}__::.x 3.39 Low review 2026-07-29
<th:t="${dfb}#foreach 4.04 Medium review 2026-07-29
bfg7448<s1﹥s2ʺs3ʹhjl7448 3.42 Low review 2026-07-29
v3.6'"()&%<zzz><ScRiPt >TiJ7(9882)</ScRiPt> 3.17 Low review 2026-07-29
v3.6&n966665=v900559 3.03 Low review 2026-07-29
v3.6 4.45 Medium review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:48
Listing SHA 175172e07035…
Force block — not fired
Score recovered no
Elapsed 21.8s